Coinsbuy Suffers $8M Cross-Chain Hack as Stolen Crypto Moves to Monero

Coinsbuy Suffers $8M Cross-Chain Hack as Stolen Crypto Moves to Monero

Last Updated:
Coinsbuy Suffers $8M Cross-Chain Hack as Stolen Crypto Moves to Monero
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Coinsbuy lost $7.9M as attackers drained Ethereum and TRON wallets in one breach.
  • ChangeNOW reportedly froze six figures as stolen funds were routed toward Monero (XMR).
  • TRM Labs logged 207 crypto hacks and $972M in losses during the first half of 2026.

Crypto payment processor Coinsbuy lost more than $7.9 million after unauthorized transfers drained digital assets from wallets operating across Ethereum and TRON.

The suspicious activity began around 13:00 UTC on Aug. 9, according to on-chain investigator SpecterAnalyst, before the stolen assets were distributed through several services.

PeckShield later tracked portions through ChangeNOW, FixedFloat, and BingX as the attacker moved proceeds away from the original wallets. ChangeNOW reportedly froze a six-figure amount.

The attacker subsequently began converting portions toward Monero, complicating blockchain tracking after funds left transparent networks. Consequently, Coinsbuy temporarily suspended deposits and withdrawals following the crypto hack.

Cross-Chain Drain Raises Questions Over Privileged Access

Coinsbuy later restored services, although the company had not released a technical postmortem or confirmed the final amount recovered by Aug. 10.

Consequently, the precise vulnerability behind the crypto hack remains unknown, and no evidence has established Ethereum or TRON as the source of the breach.

GoPlus Security reportedly described the transfers as consistent with compromised hot-wallet private keys or elevated administrator privileges. However, Coinsbuy has not confirmed either explanation.

The processor’s documentation shows that owners and administrators receive different transaction permissions, while API integrations depend on client IDs and secret credentials.

Those controls determine who can manage wallets and authorize payouts. Nevertheless, no public disclosure has identified which credentials, accounts, or systems were compromised.

After the drain, assets were fragmented across multiple services before portions were converted toward Monero. That movement reduced visibility once funds entered privacy-focused infrastructure.

$7.9M Theft Leaves Customer and Merchant Exposure Unclear

Coinsbuy has not disclosed whether the $7.9 million involved corporate assets, customer holdings, merchant balances, or a combination of several categories. As a result, the restoration of deposits and withdrawals does not confirm that every customer balance remained unaffected.

While the investigation continues, merchants and users can focus on reviewing their own accounts for signs of unauthorized activity. In particular, recent balances and transaction histories should be checked carefully for unfamiliar withdrawals or unexpected changes.

Coinsbuy’s existing security guidance also recommends changing passwords when a compromise is suspected. In addition, users should review account permissions and remove any untrusted IP addresses linked to their accounts.

Customers are also advised to enable two-factor authentication, activate transaction notifications, and regenerate API credentials when necessary. Additional controls include withdrawal thresholds, read-only permissions, and approval-required roles, which can reduce unauthorized access to transactions within merchant accounts.

The incident also comes during an especially costly year for the wider crypto industry. According to TRM Labs, attackers carried out 207 hacks and stole $972 million during the first half of 2026.

Although infrastructure and operational compromises represented only about 15% of recorded incidents, they accounted for roughly 76% of total stolen value. Consequently, those figures underscore how access-related breaches can produce disproportionately large financial losses.

Related: Bybit’s $1.5B Hack Takes a New Turn as Court Freezes Stolen Crypto

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.